ZyXEL Communications G-2000 Plus Benutzerhandbuch

Seite von 430
ZyAIR G-2000 Plus User’s Guide
Chapter 15 Firewall Screens
192
C
H A P T E R
 15
Firewall Screens
This chapter shows you how to configure your ZyAIR firewall.
15.1  Access Methods
The web configurator is, by far, the most comprehensive firewall configuration tool your 
ZyAIR has to offer. For this reason, it is recoZyAIRmmended that you configure your firewall 
using the web configurator. SMT screens allow you to activate the firewall. CLI commands 
provide limited configuration options and are only recommended for advanced users, please 
refer to the Appendix for firewall CLI commands.
15.2  Firewall Policies Overview
Firewall rules are grouped based on the direction of travel of packets to which they apply:
• LAN to LAN/ZyAIR
• WAN  to  LAN
• LAN to WAN
• WAN to WAN/ZyAIR
Note: The LAN includes both the LAN port and the WLAN.
By default, the ZyAIR’s stateful packet inspection allows packets traveling in the following 
directions:
• LAN to LAN/ZyAIR 
This allows computers on the LAN to manage the ZyAIR and communicate between 
networks or subnets connected to the LAN interface.
• LAN to WAN
By default, the ZyAIR’s stateful packet inspection blocks packets traveling in the following 
directions:
• WAN  to  LAN
• WAN to WAN/ZyAIR 
This prevents computers on the WAN from using the ZyAIR as a gateway to 
communicate with other computers on the WAN and/or managing the ZyAIR.